Legal

Privacy policy

What this site collects, what it deliberately does not, and what happens to personal data in the systems we build. Written plainly, because a privacy policy nobody can read protects nobody.

Version 1.0 · in force from 16 August 2026

The short version. This website sets no cookies, runs no analytics and loads nothing from any other company. There is no tracker on this page and no banner to click away. We collect only what you type into the contact form or the chat, and we use it to answer you. We never sell personal data and we never let client data be used as training material.

1. Who is responsible

The controller for the personal data described in this policy is the legal entity operating Exodus Labs AI, an automation studio operating internationally. Its full registered details are available on request from hello@exoduslabsai.com, and are stated on every proposal and invoice we issue.

For anything to do with your data, including a request to exercise a right, write to hello@exoduslabsai.com.

2. Two different roles, kept separate

This matters, because the answers are different.

If you are a customer of one of our clients and you want to exercise a right over your data, the fastest route is that business directly. If you write to us, we will pass it to them promptly and help them answer.

3. What this website collects

The contact form

Your name, your company name if you give one, your email address and the message you write. We use it to answer you and to prepare the audit you asked for. Nothing else.

The chat on this page

The messages you type. They are sent to a third party AI provider acting as our processor, purely so a reply can be generated, and they come straight back. If the conversation reaches a point where a person is needed, the recent exchange is forwarded to us so that we can pick it up. Do not put payment details, passwords or health information into the chat. There is no reason to, and we ask you not to.

Server logs

Our hosting provider keeps short lived technical logs, which can include an IP address, for security and to keep the site up. We do not use them to build a profile of you and we do not combine them with anything else.

What this site does not collect

This is why you have not been asked to accept anything. There is nothing to accept.

4. Why we are allowed to hold it

Where a legal basis is required, for example under the GDPR, ours is as follows.

5. Who else sees it

A small number of suppliers process data on our behalf, under contract, only on our instructions, and only for what is listed here.

We name every one of them, in full, to any client or visitor who asks. We do not list them on this page because our supply chain is part of how we work, not public information, and naming categories is what a policy is required to do. Ask and you get the list.

We never sell personal data, we never rent it, and we never share it for anyone else's advertising. We do not pass client data to any provider for use as training material for their models.

The only other cases where we would disclose data are a legal obligation we cannot lawfully refuse, or the defence of a legal claim. If we are ever compelled to hand over client data and we are permitted to tell the client, we will.

6. Where it goes

We operate internationally and our suppliers do too, so personal data may be processed in a country other than yours. Where data protected by the GDPR or a comparable regime leaves its home jurisdiction, the transfer is covered by an appropriate safeguard, in practice the European Commission's standard contractual clauses or an adequacy decision. The safeguard applying to a specific engagement is set out in the data processing agreement for that engagement.

7. How long we keep it

8. Your rights

Depending on where you are, you have some or all of the following, and we honour them for everyone rather than checking your postcode first.

Write to hello@exoduslabsai.com. We reply within thirty days, usually much sooner, and we do not charge for a reasonable request.

9. Security

Access to data is limited to the people who need it to do the work. Connections to this site and to the systems we run are encrypted in transit. Credentials are held in restricted storage, never in a document or a chat message. We review access when an engagement ends.

No system is perfectly secure and anyone who tells you otherwise is selling something. If a breach occurs that is likely to affect you, we notify the affected clients and the relevant authority within the time the applicable law requires, and we tell you what actually happened rather than a sanitised version.

10. Data inside the systems we build

When we build and run a system for a client, the personal data flowing through it belongs to that client and we act on their instructions.

11. Children

This site and our services are aimed at businesses. We do not knowingly collect personal data from children. If you believe a child's data has reached us, write to us and we will delete it.

12. Changes

If we change this policy we update the version and date at the top of the page. For a change that materially affects how we handle data of an existing client, we tell that client directly rather than relying on you noticing a date change.

Want the detail?

Ask for the full list of our suppliers, a copy of our data processing agreement or our registered details, and you get them. No form, no sales call attached.